MS11-083ï¼CVE-2011-2013ï¼ã®å®è¨¼ã³ã¼ãã試ãã¦ã¿ã
2011å¹´11æãMicrosoftããä¿®æ£ããã°ã©ã MS11-083ãæä¾ããã¾ãããMS11-083ãå ¬éãããå½åãMS11-083ã§ä¿®æ£ãããCVE-2011-2013ã¯ããªã¼ãã³ãã¦ããªãUDPãã¼ãã«ãã±ãããéä¿¡ãããã¨ã§æªç¨ã§ãããã¨ããæ°ã«ãªãã¾ããããããããã®èå¼±æ§ã®å ¬è¡¨ãããã°ããçµã¤ã¨ãã2^32ã ãUDPãã±ãããéä¿¡ããå¿ è¦ããããã¨ããèå¼±æ§ã®æªç¨ã¾ã§52æ¥ããã*1ããªã©ã®æ å ±ãã§ã¦ãã¾ããããã®å¾ã実証コードããªãªã¼ã¹ããããã¨ããããå®éã«ã©ããªãã®ããã¨æãã試ãã¦ã¿ã¾ããã
å®è¨¼çµæ
5 æ¥é㨠10 æéãå®è¨¼ã³ã¼ããå®è¡ãç¶ãã¾ããããDoS ç¶æ ï¼ããã§ã¯ Blue Screen of Death ãæ³å®ï¼ãåç¾ãã¾ããã§ãããã§ãããå®è¨¼ã³ã¼ããå®è¡ãç¶ããéãVictim ã«ã¯è² è·ããããç¶ãã¾ããã¾ãExploit Shopのブログ記事ã§æ¸ããã¦ãã Step1 ãã Step3 ã¾ã§ã 2 å試ã¿ã¾ããããDoS ç¶æ ãåç¾ãã¾ããã§ããã
å®è¨¼çµæããã®ææ³
åã®å®è¨¼ç°å¢ã§ã¯ã2^32 ã ã UDP ãã±ãããéä¿¡ãããã¨èªä½ã1æ¥å¼±ã§éæã§ãã¾ããï¼ãnetstat -s -p udpãã®çµæããå¤æï¼ããã ãUDP ã¯ãã¼ãºãã¼ãã®ãã±ããåä¿¡æ°ã 0 ã« wrap around ããã¨ãã«ãICMP ECHO REQUEST ã Victim ã«éãè¾¼ãã®ã¯ç¸å½é£ããã¨æãã¾ããå®è¨¼ã³ã¼ãã§ã¯ãä½åº¦ãä½åº¦ã wrap around ããã¦ããã®ã¿ã¤ãã³ã°ãçããããã«ã250 ã¹ã¬ãã㧠UDP ãã±ãããéãç¶ããã¨åæã« ICMP ECHO REQUEST ãéãããæ¸ããã¦ããã¨ç解ãã¾ããã
以éãå®è¨¼ç°å¢ãå®è¨¼æé ããã³å®è¨¼æã® Victim ã®æ§åãã¾ã¨ãã¾ããèå³ãããæ¹ã¯ã©ããã
å®è¨¼ç°å¢
å®è¨¼ç°å¢ã¯ä¸å³ã®éãã§ããAttacker ã§å®è¨¼ã³ã¼ããå®è¡ãã¦ãVictim ã® 80/udp ã«å¯¾ãã¦ãã±ãããéä¿¡ãã¾ããã
å®è¨¼ã³ã¼ãã«ã¯ãPacketStorm ã§å ¬éããã¦ãã こちらã使ç¨ãã¾ãããã·ã§ã«ã¹ã¯ãªããã§æ¸ããã¦ãããããã¾ãå®è¡ã㦠winnuke2011, ping.sh ãä½æããå®éã«ã¯ winnuke2011 ãå®è¡ãããã¨ã¨ãã¾ããããã®æ¥è¨ã§ç¹ã«è£è¶³ãªããå®è¨¼ã³ã¼ããã¨æ¸ããå ´åããã® winnuke2011 ãæãã¾ãã
./winnuke2011 192.168.0.102 80
å®è¨¼æé
å®è¨¼ã³ã¼ãã使ã£ã¦ããå®è¨¼ã³ã¼ããå®è¡ãç¶ããã ãã®å®è¨¼ãï¼å®è¨¼ï¼ï¼ã¨ãèå¼±æ§ãåç¾ããã¨æãããç¶æ³ãæå³çã«ä½ãå®è¨¼ãï¼å®è¨¼ï¼ï¼ã® 2 éããå®æ½ãã¾ããã
æåã¯å®è¨¼ï¼ã ãå®æ½ãã¦ãã¾ãããããnetstat -s -p udpãã«ãã Victim ãåä¿¡ããã¯ãã¼ãºãã¼ãå®ã® UDP ãã±ããæ°ã観測ã§ãããã ã£ã*2ã®ã§ãå®è¨¼ï¼ã試ãã¦ã¿ã¾ããã
å®è¨¼ï¼ï¼å®è¨¼ã³ã¼ããå®è¡ãç¶ãã
ã¾ã試ãã« Attacker ã§å®è¨¼ã³ã¼ããå®è¡ãã¦ãVictim 㧠tshark ã使ã 1 ç§éã«åä¿¡ã§ãã UDP ãã±ããæ°ã確èªãã¾ããããã®ç¢ºèªã®çµæã1 ç§éã«åä¿¡ã§ããï¼tshark ã§ãã±ãããã£ããã£ã§ããï¼UDP ãã±ããæ°ã¯ãç´ 10,000 ç¨åº¦ã§ããããã®å¤ãåºã«ãExploit Shopのブログ記事 ã® Step1 ã«è©²å½ãã INT_MAXï¼4294967295ï¼ã«éããã¾ã§ãåç´ã«è¨ç®ãã¦ãç´ 5 æ¥éç¨åº¦ãããã¨æ¦ç®ãã¾ããããã®æ¦ç®ã¯ãããã¾ã§ tshark ã§åå¾ã§ãããã±ããæ°ã«åºã¥ãã¦ãããããåèç¨åº¦ã«ãããªãã¾ããã§ãããã
ãã¨ã¯ãå®è¨¼ã³ã¼ããå®è¡ããã ãã§ãã2011å¹´11æ14æ¥(æ) 0æéãã«å®è¨¼ã³ã¼ããå®è¡ãã¦ã2011å¹´11æ20æ¥(æ¥) 10æ40åé ã¾ã§å®è¡ãç¶ãã¾ãããçµæãVictim ã DoS ç¶æ ã¨ãªããã¨ã¯ããã¾ããã§ãããç´ 5 æ¥é㨠10 æéãå®è¨¼ã³ã¼ããå®è¡ãã¦ãåç¾ã«æåããªãã£ããã¨ã«ãªãã¾ãã
å®è¨¼ï¼ï¼èå¼±æ§ãåç¾ããã¨æãããç¶æ³ãæå³çã«ä½ã
ãã®å®è¨¼ã§ã¯ãExploit Shopのブログ記事ã® Step1 ãã Step3 ã®æé ãå®è¡ãã¾ãããå ·ä½çã«ã¯æ¬¡ã®æé ãå®æ½ãã¾ãã
- ãnetstat -s -p udpãåºåçµæã®ããã¼ããªãããé©å®ç¢ºèªããªãããå®è¨¼ã³ã¼ã㧠INT_MAX(4294967295) è¿ãã¾ã§ãã±ãããéä¿¡ããããã®å¤ã INT_MAX(4294967295)ã«è¿ã¥ããããå®è¨¼ã³ã¼ããåæ¢ããã
- INT_MAX(4294967295)+1 ã¨ãªãæ®ãã®ãã±ããæ°ã ãããhping3ãã³ãã³ã㧠UDP ãã±ãããéä¿¡ãã*3ã
- ãnetstat -s -p udpãåºåçµæã®ããã¼ããªããã 0 ã« wrap around ãããã¨ã確èªãã¦ããpingãã³ãã³ã㧠ICMP ECHO REQUEST ãéä¿¡ããã
ä¸è¨æé 1 ãå®äºããã¾ã§å¤§ä½ 1æ¥ã¨1,2æéç¨åº¦ãããã¾ãããæé 3 ãå®è¡ããã¨ãã®ãnetstat -s -p udpãåºåçµæã¯ãä¸å³ã®éãã§ãã
ä¸è¨æé 1ããæé 3ã¾ã§ã 2 åå®æ½ãã¦ã¿ã¾ããããVictim ã DoS ç¶æ ã¨ãªããã¨ã¯ãªãããã®ã¾ã¾åä½ãã¦ãã¾ãããMicrosoft TechNet Blog の記事ã«ããã¨ããã®åä½ãããå¾ãã·ããªãªã«ãªãã¾ãããã®å®è¨¼æé ãæ£ãããçåãããã¾ãã--;
å®è¨¼æã® Victim ã®æ§å
å®è¨¼ã³ã¼ããå®è¡ãã¦ããã¨ããVictim ã§ã¯ CPU 使ç¨çãå®å¸¸çã«é«ããªãã¾ãããä¸å³ã¯ãå®è¨¼ã³ã¼ãå®è¡ä¸ã® Victim ã«ããããProcess Explorerãã®ã¹ã¯ãªã¼ã³ã·ã§ããã§ãããã¡ãã¨ç¢ºèªãã¦ããªãããæè¨ã§ãã¾ãããããããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¤ã¹ã®ãã©ã¤ãå¨ãã®å¦çã«è² è·ãããã£ã¦ããã¨ã¨ç解ãã¦ãã¾ãï¼é¢é£ï¼Wikipedia:デバイスドライバï¼ã
åèæ å ±
*1:PacketStorm ã§å ¬éãããå®è¨¼ã³ã¼ãã®ã³ã¡ã³ãã«æ¸ããã¦ãã¾ãã
*2:Microsoft ã® netstat の説明ã«ã¯ããnetstat -s -p udpãã®å ·ä½çãªèª¬æãããã¾ããã§ãããã80/udp ã«ãã±ãããéä¿¡ãã¦ããã¨ãããã¼ããªããã®å¤ãå¢å ãã¦ãã£ãã®ã§å¦¥å½ã¨å¤æãã¾ããã
*3:ä¾ãã°ã859108 ãã±ããã ã¨ãhping3 -c 859108 --faster --udp --destport 80 192.168.0.102ãã